Skip to main content
SAP Pentest Playbook
Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Back to homepage

Technology Overview

Description

SAP Business Technology Platform (BTP) is SAP’s multi-tenant cloud platform:

  • identity/trust management (XSUAA, IAS/IPS)
  • integration (Integration Suite/CPI, Connectivity/Destination service, Cloud Connector)
  • data/AI services (HANA Cloud, AI Core), and multiple application runtime environments

all organized under a single account hierarchy.

Account hierarchy:

Global Account
 └─ Directory (optional, for grouping)
     └─ Subaccount            ← unit of identity zone, entitlements, trust config
         └─ Space (Cloud Foundry) | Namespace (Kyma) | Cloud ABAP system

Each Subaccount gets its own XSUAA/IAS identity zone, its own set of Destinations, Trust Configuration entries, and Role Collections - it is the natural unit of scoping for a BTP assessment. Within Cloud Foundry, a Subaccount contains one or more Orgs & Spaces; the Cloud Foundry Space Developer role (routine for any app developer) is the role that matters most offensively.

Two identity planes sit above the subaccount: the SAP ID Service / S-user (SAP-managed default IdP for Global Account/Support Portal admin) and a customer’s own federated corporate IdP via IAS/IPS.

Options

Four application runtime environments, not all present on every tenant:

EnvironmentRuntimeIdentityNotes
Cloud Foundry (CF)cf push apps, buildpacksXSUAAMost common; default *.cfapps.<region>.hana.ondemand.com routes - see Cloud Foundry URL pattern/schema
KymaKubernetes + IstioXSUAA / OIDC via IstioNo single static domain; per-cluster - see Kyma URL pattern/schema
ABAP Environment (Steampunk)Cloud ABAP, RAP/CDSXSUAA + ABAP-native authRestricted ABAP; Communication Arrangements bridge to on-prem/BTP
NeoLegacy, SAP-managed JVM/HANA runtimeSAML/OAuthBeing phased out; still found in older tenants

Connectivity between BTP and on-premise systems runs through the Destination service (stores connection config, sometimes cleartext credentials and Cloud Connector (the on-prem bridge; see SAP Cloud Connector).

References